Class: Admin::ApiTokensController
- Inherits:
-
BaseController
- Object
- ActionController::Base
- BaseController
- Admin::ApiTokensController
- Defined in:
- lib/generators/open_loam/install/templates/admin/api_tokens_controller.rb
Overview
Your own API tokens — creating and listing is scoped to current_actor, so there is no path to another user's credentials. Revoking is the exception: a manager owns offboarding, and a token that outlives someone's access is the thing offboarding is supposed to end.
Constant Summary
Constants included from Pagination
Instance Method Summary collapse
Methods inherited from BaseController
Methods included from Pagination
Instance Method Details
#create ⇒ Object
20 21 22 23 24 25 26 |
# File 'lib/generators/open_loam/install/templates/admin/api_tokens_controller.rb', line 20 def create token = api_tokens.create!(label: params[:label].presence || "API token") # The only time the plaintext exists: only its digest is stored, so this # screen is genuinely the last chance to copy it. redirect_to admin_api_tokens_path, flash: { token: token.token } end |
#destroy ⇒ Object
28 29 30 31 32 33 34 35 36 |
# File 'lib/generators/open_loam/install/templates/admin/api_tokens_controller.rb', line 28 def destroy # Tenant-scoped by the default scope, so another tenant's token is not # merely forbidden here — it is not findable. record = OpenLoam::ApiToken.find(params[:id]) require_role!(:manager) unless record.user_id == current_actor.id record.destroy! redirect_to admin_api_tokens_path end |
#index ⇒ Object
13 14 15 16 17 18 |
# File 'lib/generators/open_loam/install/templates/admin/api_tokens_controller.rb', line 13 def index @records = api_tokens.order(created_at: :desc) # Only the label, owner and usage — never a token value, which no longer # exists in a readable form anyway. @tenant_records = manager? ? OpenLoam::ApiToken.where.not(user_id: current_actor.id).order(created_at: :desc) : [] end |